Description
Cross-site scripting (XSS) vulnerability in admin/index.php in phpList before 2.10.19 allows remote attackers to inject arbitrary web script or HTML via the unconfirmed parameter to the user page.
Remediation
References
Related Vulnerabilities
Telerik Web UI Inadequate Encryption Strength Vulnerability (CVE-2017-11317)
WordPress Plugin Google Calendar Events Cross-Site Scripting (2.0.3.1)
WordPress Plugin Photo Gallery by 10Web-Mobile-Friendly Image Gallery SQL Injection (1.5.54)
WordPress Plugin WPJobBoard Cross-Site Scripting (5.6.4)
WordPress Plugin Drag & Drop File Uploader 'dnd-upload.php' Arbitrary File Upload (0.1)